Data processing agreement
Version 1.0. Draft, legal review required. An annex to the terms of service, applying automatically to every restaurant that uses the service.
1. The parties
This data processing agreement ("the Processing Agreement") applies between the restaurant that holds an account in the service ("the Controller") and Marx Media AB, company registration number 556942-0796 ("the Processor", "we"). The Processing Agreement forms an integral part of the terms of service and applies for as long as we process personal data on behalf of the Controller.
2. Background and roles
The restaurant is the controller of the data that guests provide when they order. We provide the ordering page and process the data solely in order to deliver the service. For data about the restaurant's own account, such as contact details, login and accounting records, we are ourselves the controller, and that processing is covered not by this Processing Agreement but by our privacy policy.
3. Subject matter, duration, nature and purpose
We process personal data in order to receive, display, confirm and give notice of orders for collection and home delivery, and for the operation, security and support of the service. The processing continues for as long as the restaurant has an active account. The categories of data subjects and of personal data are set out in Annex A.
4. Instructions
We process personal data only in accordance with the Controller's documented instructions. Use of the service under the terms of service, including the settings the restaurant itself chooses in the admin view, constitutes such instructions. Further instructions are to be given in writing to help@takeawayer.com. If, in our assessment, an instruction infringes the GDPR or other applicable data protection legislation, we will inform the Controller without delay. If Union law or Swedish law requires us to process data beyond the instructions, we will inform the Controller before the processing, unless the law prohibits it.
5. Confidentiality
Persons who are given access to the personal data at our end are bound by a duty of confidentiality. Access is given only to those who need it in order to deliver the service.
6. The Controller's obligations
The Controller is responsible for there being a legal basis for the processing, for the information given to guests, and for not entering special categories of personal data (article 9 GDPR) into free-text fields such as the message box at checkout.
7. Security measures
We take the technical and organisational measures required under article 32 GDPR, in the main the following:
- Encryption in transit. All traffic to the service goes over TLS (HTTPS). The data is stored encrypted at rest at the database provider.
- Access control. The restaurant's staff log in with a one-time link by email; we store no passwords. Each restaurant reaches only its own orders and its own menu.
- Logging. Changes to settings and menu are logged with the time and who made them.
- Resilience. Rate limiting on the ordering and login routes. Error monitoring is carried out without personal data.
- Backup and restore. The database is backed up daily, so that the data can be made available again within a reasonable time after an incident.
- Storage minimisation. Name, telephone number, email address and message are deleted automatically 90 days after the order. The amount of the order is kept anonymously for the restaurant's accounts.
8. Sub-processors
The Controller gives us general prior authorisation to engage sub-processors. Those engaged at the time this agreement is entered into are set out in Annex B. We impose on each sub-processor the same obligations as follow from this Processing Agreement and are liable for their processing as for our own.
A change or addition of a sub-processor is notified at least 30 days in advance. The Controller may then object on reasonable grounds; if we cannot offer a reasonable alternative, the Controller is entitled to terminate the service free of charge with effect from the day the change takes effect.
9. Transfers to third countries
The personal data is stored within the EU/EEA (Frankfurt). Some sub-processors are established outside the EU/EEA; for these, transfers are made on the basis of the European Commission's standard contractual clauses or another valid transfer tool, supplemented by the safeguards required. Annex B states where each sub-processor processes the data.
10. Assistance with data subjects' rights
If a guest approaches us directly, we refer them to the restaurant and inform the Controller without undue delay. We assist with appropriate technical and organisational measures so that the Controller can respond to requests for access, rectification, erasure, restriction, data portability and objection. The restaurant can itself see and change its order data in the admin view.
11. Personal data breach
We notify the Controller without undue delay after becoming aware of a personal data breach concerning data we process on behalf of the Controller. The notification describes the nature of the breach, the categories and number of those affected so far as they are known, the likely consequences and the measures taken. We assist the Controller with notification to the Swedish Authority for Privacy Protection and with information to the data subjects.
12. Other assistance
We assist the Controller with security under article 32, data protection impact assessment under article 35 and prior consultation under article 36, to the extent reasonable having regard to the nature of the processing and the information available to us.
13. Erasure and return
When the service ends we erase the personal data within 90 days, unless Union law or Swedish law requires continued storage; accounting records are kept for seven years under the Swedish Accounting Act. Before erasure, the Controller can export its menu as CSV and its orders through the admin view.
14. Audit
We give the Controller the information needed to demonstrate compliance with the obligations in article 28 GDPR, and allow for and contribute to audits. Audits are carried out at the Controller's expense, at most once a year unless an incident or a requirement from an authority warrants more, and after at least 30 days' notice.
15. Liability, changes and disputes
The limitation of liability in the terms of service applies to this Processing Agreement as well, to the extent mandatory law permits. Changes are notified at least 30 days in advance. In the event of a conflict between this Processing Agreement and the terms of service, the Processing Agreement prevails on questions of the processing of personal data. Swedish law applies and disputes are heard by the general courts, with Uppsala tingsrätt as the court of first instance.
Annex A - The processing
Categories of data subjects: the restaurant's guests who place an order, and the restaurant's own staff with access to the admin view.
Categories of personal data: name, telephone number, email address, free-text message to the kitchen, the contents and amount of the order, the collection time chosen, and, for home delivery, the delivery address. For staff: email address and role. Technical logs for operation and security.
Special categories of personal data: not requested, and not to be entered into the service. Information about allergies may occur if a guest writes it in the message field; it is then processed as part of the order and deleted with it.
Processing operations: collection, storage, display to the restaurant, sending of confirmation and status emails, production of figures for the restaurant's own sales follow-up, and automatic erasure after 90 days.
Annex B - Sub-processors
| Sub-processor | Service | Place of processing |
|---|---|---|
| Supabase | Database (orders, menu, accounts) | EU (Frankfurt) |
| Vercel Inc. | Hosting of the web service and storage of uploaded images | EU, with support from the USA |
| Resend | Sending of order, status and login emails | USA |
| Functional Software, Inc. (Sentry) | Error monitoring, without personal data | USA |
| Umami Software, Inc. | Visit statistics for takeawayer.com, not for the restaurant's ordering page, without cookies | EU, with support from the USA |
| OpenStreetMap Foundation | Address lookup to determine whether a delivery address lies within the restaurant's delivery area | United Kingdom |
The list is kept up to date on this page. Questions about the processing: help@takeawayer.com.